many thanks. issue resolved: cert configuration matter. all good. but there still is the matter of the OP's problem. can he access site with compiler option? also, it looks like server is his. if, in fact, the cert is valid, then his issue might be the same as mine: he needs to point his server to where "fullchain.pem" is located (instead of "cert.pem"). that apparently solves the "Trust anchor for certification path not found" exception. when i made the change, i no longer needed the compiler option. since letsencrypt automatically renews its certs every 3 months, the configuration could be the problem.